Apache HTTP Server Security Update Advisory (CVE-2024-39884)

Overview

The Apache HTTP Server Project(https://httpd.apache.org/ ) has released a security update that fixes vulnerabilities in products supplied by the organization. users of affected products are advised to update to the latest version.

 

Affected Products

Apache HTTP Server version 2.4.60

Resolved Vulnerabilities

Vulnerability that could result in source code disclosure of local content in some situations when indirectly requesting files using “AddType” and similar configurations (CVE-2024-39884)

Vulnerability Patches

Apache HTTP Server version 2.4.61

Product-specific Vulnerability Patches were made available in the July 3, 2024 update. For more information about the vulnerability updates, please refer to the Referenced Sites below.

Referenced Sites

[1] CVE-2024-39884 Detail

https://nvd.nist.gov/vuln/detail/CVE-2024-39884

[2] Fixed in Apache HTTP Server 2.4.61

https://httpd.apache.org/security/vulnerabilities_24.html